MALICIOUS — 5a349836c0c4b3c5a09107568e4cb4353d449ce5f82b0f594dc54d6a5f277f46
MALICIOUS — 5a349836c0c4b3c5a09107568e4cb4353d449ce5f82b0f594dc54d6a5f277f46 is a html sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the HiddenSpam family. 4 of 54 detection engines flagged it.
Identification
- SHA-256:
5a349836c0c4b3c5a09107568e4cb4353d449ce5f82b0f594dc54d6a5f277f46 - SHA-1:
771f984e1aef85b0b62ada9ef81d22433d7ace64 - MD5:
34f80cc156ab6ee2fa939a176047ef10 - ssdeep:
384:SIDTJaKeNOqU0QwXPVHYaYsochInb0KQk97FG6h2QUtcmcyyYpY++SmuMyK2O2/a:SIE/JxYJ3Wm - TLSH:
T1792B3314A2287A5A04F5891B6004CDA8C0C6E21F337BE6B6CFCDEB14F576DA29C1B715 - Submitted as: 5a349836c0c4b3c5a09107568e4cb4353d449ce5f82b0f594dc54d6a5f277f46
- File type: html · Size: 22751 bytes
- Verdict: malicious (99/100) · Family: HiddenSpam
Detections (4 of 54 engines)
- ClamAV (daily): Js.Trojan.Obfus-633
- Microsoft Defender: Trojan:JS/HideLink.A
- Emsisoft (Emergency Kit): Generic.JS.HiddenSpam.1.1FCCBF0B
- Kaspersky (KVRT): Trojan-Downloader.JS.Agent.hbs
Why this verdict
The malicious score of 99/100 is the fusion of 8 weighted signals:
- ClamAV (daily) flagged Js.Trojan.Obfus-633 (rule
Js.Trojan.Obfus-633) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:JS/HideLink.A (rule
Trojan:JS/HideLink.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Generic.JS.HiddenSpam.1.1FCCBF0B (rule
Generic.JS.HiddenSpam.1.1FCCBF0B) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Downloader.JS.Agent.hbs (rule
Trojan-Downloader.JS.Agent.hbs) - engine signal, weight 0.55, confidence 0.85 - Contacted 2 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://gmpg.org/xfn/11, https://www.pelada-movie.com/blog/wp-content/themes/pelada/style.css, http://www.pelada-movie.com/blog/xmlrpc.php - static signal, weight 0.35, confidence 0.60
- Extracted generic config (18 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
- Memory forensics: 2 finding(s) elsewhere in the guest, not attributed to this sample, e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.05, confidence 0.30
Dynamic analysis (windows)
279 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- windows.msn.com
- www.msn.com
- odc.officeapps.live.com
- settings-win.data.microsoft.com
- www.bing.com
Dropped files
- 5f6986496a3163ce3acf46035a0677e5aa50f800a1b2da53948e5b8dcf73c333 -
5f6986496a3163ce3acf46035a0677e5aa50f800a1b2da53948e5b8dcf73c333
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://gmpg.org/xfn/11
- https://www.pelada-movie.com/blog/wp-content/themes/pelada/style.css
- http://www.pelada-movie.com/blog/xmlrpc.php
- http://www.pelada-movie.com/blog/?m=201301
- http://www.pelada-movie.com/blog/?m=200906
- http://www.pelada-movie.com/blog/?m=200904
- http://www.pelada-movie.com/blog/?m=200810
- http://www.pelada-movie.com/blog/?m=200808
- http://www.pelada-movie.com/blog/?m=200807
- http://www.pelada-movie.com/blog/?m=200806
- http://www.pelada-movie.com/blog/?m=200805
- http://www.pelada-movie.com/blog/?m=200712
- http://www.pelada-movie.com/blog/?m=200711
- http://www.pelada-movie.com/blog/?m=200710
- http://www.pelada-movie.com/blog/?m=200709
- http://www.pelada-movie.com/blog/?m=200707
- http://www.pelada-movie.com/blog/?feed=rss2
- http://www.pelada-movie.com/blog/?feed=comments-rss2
- http://www.pelada-movie.com/blog/xmlrpc.php?rsd
- http://www.pelada-movie.com/blog/wp-includes/wlwmanifest.xml
- http://www.pelada-movie.com/blog
- http://twitoaster.com/peladamovie/
- http://www.pelada-movie.com/blog/wp-content/plugins/twitoaster/style.css?ver=1.3.5
Embedded domains
- www.w3.org
- gmpg.org
- www.pelada-movie.com
- twitoaster.com
- www.amai.org
- dioceseofmpumalanga.co.za
- kingsofwar.org.uk
- fwmedia.co.uk
- www.afca.com
- www.sydneyangels.net.au
- www.ascls-cne.org
- fsx.co.za
- www.diveo.net
- ballerblogger.com
- www.cyclopedie.fr
- opengear.org.uk
- www.alaskageology.org
- opentec.org
- allfootballgames.co.uk
- www.twitter.com
- www.jbreed.com
- www.wordpress.org
- southerndocumentaryfund.org
- www.facebook.com
- app.expressemailmarketing.com
Embedded IP addresses
- 4.150.223.113
- 52.123.252.224
- 4.230.171.124
- 172.215.188.232
- 4.144.132.114
- 74.178.240.51
- 74.178.240.61
- 20.42.73.31
- 104.208.16.94
- 104.18.33.89
- 172.66.2.5
- 52.110.12.32
- 52.110.12.14
- 52.148.114.188
- 72.153.5.131
- 52.110.12.33
- 52.110.12.55
More HiddenSpam samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report